What happened
NVD published CVE-2026-102879 (CVSS 5.0 v3.1) on 2026-09-29. ClaraVerse's download/scrape agent tools contain SSRF protection bypasses enabling internal/IMDS requests from the GenAI agent server (issue #254).
Why it matters
Agent tools with fetch/scrape capabilities are the classic SSRF surface in LLM application servers — the flaw lets an authenticated agent user reach internal services and cloud metadata (IMDS credentials) from the AI deployment host, though the package is niche.
Attack vector
Authenticated users invoke the download_file / scrape_web agent tools with URLs that bypass hostname validation and IPv6-transition-address filtering, making the server request internal services and cloud-instance metadata endpoints (SSRF, CWE-918).
Affected systems
ClaraVerse through 0.3.1 (download_file and scrape_web agent tools, backend/internal/security/ssrf.go)
Mitigation
Harden the SSRF validator (resolve DNS before allowlist checks, block IPv6 transition encodings and non-global ranges); upstream fix pending (issue #254).